GNOME.libxslt is vulnerable to Type Confusion
31
Low Risk
While compiling a stylesheet, exsltFuncResultComp follows parent pointers to check that func:result is under func:function. If that ancestor is missing, the check continues onto the document node and reads the ns slot, which on a document node holds the compression and standalone integers, so a stylesheet with a misplaced func:result can crash the process. The fix stops the parent check at the document node.
You are affected if you are using a version that falls within the vulnerable range and you load untrusted XSLT that places func:result outside func:function.
GNOME.libxslt is vulnerable to Type Confusion in versions 0.0.1 - 1.1.43.
Upgrade the GNOME.libxslt library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.